8.5

CVSS3.1

CVE-2025-32574 - WordPress WPGYM plugin <= 65.0 - SQL Injection vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mojoomla WPGYM allows SQL Injection. This issue affects WPGYM: from n/a through 65.0.

๐Ÿ“… Published: July 16, 2025, 11:28 a.m. ๐Ÿ”„ Last Modified: April 28, 2026, 4:12 p.m.

7.1

CVSS3.1

CVE-2025-46500 - WordPress Wordpress Auto Spinner plugin <= 3.26.0 - Reflected Cross Site Scripting (XSS) vulnerabilโ€ฆ

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ValvePress Wordpress Auto Spinner wp-auto-spinner allows Reflected XSS.This issue affects Wordpress Auto Spinner: from n/a through <= 3.26.0.

๐Ÿ“… Published: July 16, 2025, 11:28 a.m. ๐Ÿ”„ Last Modified: April 23, 2026, 3:30 p.m.

7.1

CVSS3.1

CVE-2025-47554 - WordPress CSS3 Compare Pricing Tables for WordPress plugin <= 11.6 - Reflected Cross Site Scriptingโ€ฆ

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuanticaLabs CSS3 Compare Pricing Tables for WordPress css3_web_pricing_tables_grids allows Reflected XSS.This issue affects CSS3 Compare Pricing Tables for WordPress: from n/a through <= 11.6.

๐Ÿ“… Published: July 16, 2025, 11:28 a.m. ๐Ÿ”„ Last Modified: April 23, 2026, 3:30 p.m.

8.5

CVSS3.1

CVE-2025-47645 - WordPress ELEX WooCommerce Advanced Bulk Edit Products, Prices & Attributes plugin <= 1.4.9 - Subscโ€ฆ

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ELEXtensions ELEX WooCommerce Advanced Bulk Edit Products, Prices & Attributes elex-bulk-edit-products-prices-attributes-for-woocommerce-basic allows SQL Injection.This issue affects ELEX WooCommerโ€ฆ

๐Ÿ“… Published: July 16, 2025, 11:28 a.m. ๐Ÿ”„ Last Modified: April 23, 2026, 3:30 p.m.

7.1

CVSS3.1

CVE-2025-47652 - WordPress Infility Global plugin <= 2.13.4 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Infility Infility Global infility-global allows Reflected XSS.This issue affects Infility Global: from n/a through <= 2.13.4.

๐Ÿ“… Published: July 16, 2025, 11:28 a.m. ๐Ÿ”„ Last Modified: April 23, 2026, 3:30 p.m.

7.1

CVSS3.1

CVE-2025-48291 - WordPress Contest Gallery <= 26.0.6 - Cross Site Scripting (XSS) Vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery contest-gallery allows Stored XSS.This issue affects Contest Gallery: from n/a through <= 26.0.6.

๐Ÿ“… Published: July 16, 2025, 11:28 a.m. ๐Ÿ”„ Last Modified: April 23, 2026, 3:31 p.m.

9.1

CVSS3.1

CVE-2025-48300 - WordPress Groundhogg plugin <= 4.2.1 - Arbitrary File Upload vulnerability

Unrestricted Upload of File with Dangerous Type vulnerability in Adrian Tobey Groundhogg groundhogg allows Upload a Web Shell to a Web Server.This issue affects Groundhogg: from n/a through <= 4.2.1.

๐Ÿ“… Published: July 16, 2025, 11:28 a.m. ๐Ÿ”„ Last Modified: April 23, 2026, 3:31 p.m.

6.5

CVSS3.1

CVE-2025-48339 - WordPress Profiler - What Slowing Down Your WP <= 1.0.0 - Broken Access Control Vulnerability

Missing Authorization vulnerability in activity-log.com Profiler - What Slowing Down Your WP allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Profiler - What Slowing Down Your WP: from n/a through 1.0.0.

๐Ÿ“… Published: July 16, 2025, 11:28 a.m. ๐Ÿ”„ Last Modified: April 28, 2026, 4:12 p.m.

7.1

CVSS3.1

CVE-2025-48345 - WordPress Contact Form 7 Editor Button plugin <= 1.0.0 - Reflected Cross Site Scripting (XSS) vulneโ€ฆ

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in arisoft Contact Form 7 Editor Button cf7-editor-button allows Reflected XSS.This issue affects Contact Form 7 Editor Button: from n/a through <= 1.0.0.

๐Ÿ“… Published: July 16, 2025, 11:28 a.m. ๐Ÿ”„ Last Modified: April 23, 2026, 3:31 p.m.

7.1

CVSS3.1

CVE-2025-49031 - WordPress SMu Manual DoFollow plugin <= 1.8.1 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Stefan M. SMu Manual DoFollow manuall-dofollow allows Reflected XSS.This issue affects SMu Manual DoFollow: from n/a through <= 1.8.1.

๐Ÿ“… Published: July 16, 2025, 11:28 a.m. ๐Ÿ”„ Last Modified: April 23, 2026, 3:31 p.m.
Total resulsts: 349182
Page 4620 of 34,919
ยซ previous page ยป next page
Filters